QID 730840
Date Published: 2023-07-18
QID 730840: Jfrog Artifactory Weak Password Vulnerability
JFrog Artifactory is the only Universal Repository Manager supporting all major packaging formats, build tools and CI servers.
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.
Affected Versions:
JFrog Artifactory prior to 6.17
QID Detection Logic:(Unauthenticated)
This QID checks for the version of Artifactory on the target.
On successful exploitation it may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory.
Solution
Customers are suggested to upgrade to JFrog Artifactory 6.17 or later or later.
Vendor References
CVEs related to QID 730840
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JFrog Artifactory 6.17.0 |
|